open-source.sgit.ai / about

Dinis Cruz

This site is my position on open source — what it is for, how to practise it, and the history that supports it. It is written from the experience of building, open-sourcing and running security software and companies, and it is the strategy those companies actually run on: everything they ship is open source, and so are their investor materials.

The record

RoleWhat it involved
Founder, sgit.aiEncrypted vaults with git semantics — clone, commit, branch and merge files encrypted before they leave your machine — under Apache-2.0, and the network of nineteen sites of which this is one. Each site publishes its argument before its implementation, so the commitments are checkable.
Founder, sgraph.aiWhere the strategy turns into revenue: the commercial home of SG/Send, the secure file-sharing service built on the open-source sgit layer, and the place that sells access to SG/Vaults — hosted sgit vaults. The code stays Apache-2.0; what is sold is the running, maintained, certified service, which is exactly where this site says the commercial line belongs.
Founder, MyFeeds.aiRole-aware cybersecurity briefings built on semantic knowledge graphs — CISO, engineer and board views of the same news, with source attribution. 100% open source, serverless, no vendor lock-in. The seed pitch, use of funds and unit economics are published in the open.
Founder, The Cyber BoardroomAn AI-powered platform for the conversation between technical security teams and the board — bridging the two with knowledge-graph technology. Apache-2.0, with the community edition, the website and the automation in public repositories.
Founder, RiskMandate.aiThe business risk layer for autonomous systems. The newest of the startups, alongside VoiceDebrief.
Founder, VoiceDebrief.aiVoice recordings into transcripts and debriefs, entirely in the browser — no account, and nothing uploaded to a server. The "ask for keys at run time, store nothing" habit from the founders' page, shipped as a product.
Former OWASP Board memberAnd organiser of the OWASP Summits — Lisbon 2011 and Woburn 2017, the working-session format with "no spectators, only participants" that the Open Security Summit series went on to build on. Current open-source work still ships under the owasp-sbot organisation, with MGraph-DB publicly credited to the OWASP community.
Creator, the O2 PlatformThe OWASP static-analysis engine of 2010–2012, and the first of a line of open-source tooling that continues in the osbot-* and mgraph-* families, memory_fs, Issues-FS and sgit-aiall Apache-2.0, all on PyPI.

Built in the open, including the parts most companies keep closed

The argument on this site is that open source is a strategy rather than a charity, and the strongest evidence I can offer for it is that I run companies on it. That extends past the code:

Interests declared

I run companies whose strategy this is, and which sell maintenance, quality and certification rather than code — the market this site describes is one I intend to be in. Read the argument knowing that. Two things are built in to keep it honest:

Reach me, or correct me

↗ LinkedIn is the fastest route. Corrections and requests for this site are tracked in the open on the comms board, and the repository takes issues and pull requests. If you find something wrong here, I would rather know.